CVE-2016-20074 PUBLISHED

WordPress Lazy Content Slider Plugin 3.4 CSRF

Assigner: VulnCheck
Reserved: 15.06.2026 Published: 15.06.2026 Updated: 15.06.2026

WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify plugin configuration parameters like lzcs_color and lzcs_count.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CVSS Score: 5.3

Product Status

Vendor leethompson
Product Lazy Content Slider Plugin
Versions
  • Version 3.4 is affected

Credits

  • Persian Hack Team finder

References

Problem Types

  • Cross-Site Request Forgery (CSRF) CWE